cKure Red
Открыть в Telegram
The director's cut on critical feeds from InfoSec world 🌎 Main Channel: @cKure ☕️ or queries email us 📨 i@ckure.org
Больше2 562
Подписчики
+324 часа
+67 дней
+5530 день
Загрузка данных...
Похожие каналы
Облако тегов
Входящие и исходящие упоминания
---
---
---
---
---
---
Привлечение подписчиков
июнь '26
июнь '26
+44
в 2 каналах
май '26
+82
в 1 каналах
Get PRO
апрель '26
+81
в 2 каналах
Get PRO
март '26
+69
в 2 каналах
Get PRO
февраль '26
+51
в 2 каналах
Get PRO
январь '26
+119
в 2 каналах
Get PRO
декабрь '25
+81
в 2 каналах
Get PRO
ноябрь '25
+86
в 1 каналах
Get PRO
октябрь '25
+54
в 3 каналах
Get PRO
сентябрь '25
+56
в 3 каналах
Get PRO
август '25
+34
в 2 каналах
Get PRO
июль '25
+39
в 3 каналах
Get PRO
июнь '25
+41
в 2 каналах
Get PRO
май '25
+71
в 3 каналах
Get PRO
апрель '25
+36
в 1 каналах
Get PRO
март '25
+37
в 2 каналах
Get PRO
февраль '25
+50
в 1 каналах
Get PRO
январь '25
+29
в 1 каналах
Get PRO
декабрь '24
+75
в 3 каналах
Get PRO
ноябрь '24
+112
в 3 каналах
Get PRO
октябрь '24
+65
в 1 каналах
Get PRO
сентябрь '24
+110
в 1 каналах
Get PRO
август '24
+114
в 1 каналах
Get PRO
июль '24
+127
в 6 каналах
Get PRO
июнь '24
+53
в 2 каналах
Get PRO
май '24
+70
в 2 каналах
Get PRO
апрель '24
+158
в 26 каналах
Get PRO
март '24
+95
в 2 каналах
Get PRO
февраль '24
+153
в 24 каналах
Get PRO
январь '24
+114
в 2 каналах
Get PRO
декабрь '23
+96
в 1 каналах
Get PRO
ноябрь '23
+28
в 1 каналах
Get PRO
октябрь '23
+34
в 1 каналах
Get PRO
сентябрь '23
+22
в 0 каналах
Get PRO
август '23
+32
в 0 каналах
Get PRO
июль '23
+31
в 0 каналах
Get PRO
июнь '23
+32
в 0 каналах
Get PRO
май '23
+16
в 0 каналах
Get PRO
апрель '23
+29
в 0 каналах
Get PRO
март '23
+22
в 0 каналах
Get PRO
февраль '23
+18
в 0 каналах
Get PRO
январь '23
+28
в 0 каналах
Get PRO
декабрь '22
+33
в 0 каналах
Get PRO
ноябрь '22
+33
в 0 каналах
Get PRO
октябрь '22
+12
в 0 каналах
Get PRO
сентябрь '22
+14
в 0 каналах
Get PRO
август '22
+38
в 0 каналах
Get PRO
июль '22
+34
в 0 каналах
Get PRO
июнь '22
+30
в 0 каналах
Get PRO
май '22
+38
в 0 каналах
Get PRO
апрель '22
+40
в 0 каналах
Get PRO
март '22
+51
в 0 каналах
Get PRO
февраль '22
+23
в 0 каналах
Get PRO
январь '22
+39
в 0 каналах
Get PRO
декабрь '21
+243
в 0 каналах
| Дата | Привлечение подписчиков | Упоминания | Каналы | |
| 16 июня | +1 | |||
| 15 июня | +3 | |||
| 14 июня | +1 | |||
| 13 июня | +2 | |||
| 12 июня | +2 | |||
| 11 июня | +1 | |||
| 10 июня | 0 | |||
| 09 июня | +2 | |||
| 08 июня | +3 | |||
| 07 июня | +2 | |||
| 06 июня | +4 | |||
| 05 июня | +1 | |||
| 04 июня | +2 | |||
| 03 июня | +6 | |||
| 02 июня | +9 | |||
| 01 июня | +5 |
Посты канала
Exploiting CVE-2024-1065 via the Page Cache!
A strategy for physical-page UAFs in MIGRATE_MOVABLE, where Dirty Pagetable and Dirty Cred don't apply.
https://kuzey.rs/posts/MaliUAF/
Demonstrated on the Mali GPU UAF found by Project Zero.
| 2 | Free research papers
https://sci-bot.ru/ | 666 |
| 3 | 📡🅰️🅰️🅰️❎❎🅰️🅰️🅰️🅰️
PimEyes.Com | 995 |
| 4 | 👩💻 Performing RCE in Internet Explorer via clickjacking!
Credits: Igor Sak-Sakovsky's (𝕏 | Psych0tr1a)
https://swarm.ptsecurity.com/the-click-that-shouldnt-have-worked-rce-via-clickjacking-in-internet-explorer/ | 1 078 |
| 5 | 📡🛰 For 19 years, GPS satellites have secretly broadcast a “numbers station” in their public signals. We decoded 12M messages: a 2011 flash where 31 of 32 satellites flipped in hours, “ghost” substrings repeating years apart, and a “TEXT” prefix spreading now.
https://lsc-pagepro.mydigitalpublication.com/publication/?i=865273&p=62&view=issueViewer
https://github.com/sjmurdoch/gps-special-messages
https://x.com/i/status/2061829547289387209 | 1 504 |
| 6 | 🔗🆒🆒🔤🆒🆒🆒🆒
Transfer data between devices using just QR codes!
QR-Beam — A browser-based data transfer tool where both sender and receiver run entirely client-side via JavaScript. No installation, simple mobile-friendly UI, and designed for real-world use.
The idea isn't new, but was focused on turning it into a practical, production-ready solution with several improvements over existing PoCs.
Beta: https://ckure.org/rx/QR-Beam | 1 |
| 7 | 🔗🆒🆒🔤🆒🆒🆒🆒
Transfer data between devices using just QR codes!
QR-Beam — A browser-based data transfer tool where both sender and receiver run entirely client-side via JavaScript. No installation, simple mobile-friendly UI, and designed for real-world use.
The idea isn't new, but was focused on turning it into a practical, production-ready solution with several improvements over existing PoCs.
Beta: https://ckure.org/rx/QR-Beam | 1 |
| 8 | 🔗🆒🆒🔤🆒🆒🆒🆒
Transfer data between devices using just QR codes!
QR-Beam — A browser-based data transfer tool where both sender and receiver run entirely client-side via JavaScript. No installation, simple mobile-friendly UI, and designed for real-world use.
The idea isn't new, but was focused on turning it into a practical, production-ready solution with several improvements over existing PoCs.
Beta: https://ckure.org/rx/QR-Beam | 1 077 |
| 9 | 😔 Mini Plasma Zero-Day by Chaotic Eclipse (aka Nightmare Eclipse) with a total of 6 0-Days in 6 weeks.
Official blog:
https://deadeclipse666.blogspot.com
https://blog.barracuda.com/2026/05/19/nightmare-eclipse-zero-days-grudge | 1 191 |
| 10 | 📱Anthropic co-founder says there is a "real possibility that AI will displace human labor at a very large scale," and that supporting those people "will be a moral imperative of historic proportions."
And we do not have a mechanism while most of the control of AI is with few wealthy nations and individuals. | 871 |
| 11 | 🔠🔠🔠🔠🔠🔠🔠➖🔠🔠🔠
https://www.theverge.com/tech/935202/flipper-devices-one-zero-wireless-multi-tool-linux-open-source-computer | 1 384 |
| 12 | 🤖 🆒🆒🆒🆒🆒🆒
Earlier today Cloudflare's CSO shared how they tested Anthropic Mythos using an unreleased 8-stage vulnerability-discovery agent.
Opus implemented the agent and it works via Claude SDK with a Pro or Max subscription, no API.
https://github.com/evilsocket/audit
𝕏 | Simone | 1 484 |
| 13 | 🚀40K Starlink terminals hacked to lure Russians into a cyber trap as per anti-Russia propaganda news.
40,000 Starlink terminals go dark. Russian soldiers scramble for answers and turn to Telegram. They don’t realise they’ve just walked into a trap. The journalists travelled across Ukraine from Lviv to the front line in Zaporizhzhia to uncover a pretty audacious cyber operation. Meet Goldfinger and the 256 Cyber Assault Brigade and Yaro, and the 128th Mechanised Brigade, holding the line in the south. | 1 376 |
| 14 | 🤩 ❗️❗️❗️❗️❗️❗️
LLM used to make a Zero-Day by APT group on a popular software.
The zero day was a 2FA bypass via logic bug 🪲
Security researchers at Alphabet’s Google said they believe a cybercrime group used artificial intelligence to create a hacking tool that can bypass defenses in a widely-used tool to administer computer systems. The scheme, which was foiled when Google alerted the tool developer, would mark the first time that Google’s Threat Intelligence Group caught a hacker using an AI-generated “zero-day” in such a way, according to a report published Monday. | 1 195 |
| 15 | ⚠️⚠️⚠️⚠️⚠️⚠️
CVE-2026-0073: Critical Android Zero-Click, Zero-Day exploit in wireless debugging (if enabled) can allow adjacent hacker (in same network) to execute code as shell user. | 1 426 |
| 16 | 🅰️🅰️🅰️🔢🅰️🅰️🅰️
Devcore team chained ⛓️💥 4 logic bugs to achieve sandbox escape in Microsoft Edge in Pwn²Own 2026, Berlin. | 1 187 |
| 17 | 🤖 Mythos finds a curl vulnerability.
https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/ | 1 296 |
| 18 | 🆒🆒🆒🆒🔢🔢
FAST16 — Pre-Stuxnet Sabotage Malware (2005)
- Referenced in Shadow Brokers (2017) leak (“NOTHING TO SEE HERE”)
- Compiled ~2005 → ~5 years before Stuxnet
- Type: Sabotage malware (not espionage)
Target
- High-precision engineering / simulation software
- Includes LS-DYNA, PKPM, MOHID
- Used for physics, impact, and advanced simulations (incl. nuclear-related domains)
Technique
- Kernel driver: "fast16.sys"
- In-memory patching of target processes
- Injects subtle calculation errors (floating-point manipulation)
- Goal: corrupt outputs while appearing normal
Propagation
- Worm-like spread via weak Windows network shares
Attribution
- Not confirmed
- Strong suspicion: US or allied origin (based on NSA-linked leak context)
Note
- LS-DYNA ≠ purely “explosive software”
- Broader simulation usage; “explosive calculations” is a subset use case | 1 781 |
| 19 | IoT side channel (correlation) attack using WiFi.
Heuristic surveillance data is both widely under-reported and difficult to mitigate without tossing your devices and living in the stone age. | 817 |
| 20 | 💽 Phantomdrive is an open-source USB drive designed to conceal its actual capacity. Upon initial insertion, the device presents itself as an 8GB disk. To access the secondary partition, a file named "unlock.txt" must be created, followed by the entry of the password; the drive will subsequently unmount and remount, revealing the remaining data. All data is encrypted in place using an AES-256 key derived from the password. This mechanism is fundamentally different from how Veracrypt operates. | 1 520 |
Уже доступно! Исследование Telegram 2025 — ключевые инсайты года 
